CVE Database /
CVE-2026-54191
CVE · High
CVE-2026-54191 — Pods – Custom Content Types and Fields [pods] < 3.3.9
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-54191
|
Pods – Custom Content Types and Fields [pods] < 3.3.9 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
High
7.1
|
< 3.3.9
|
3.3.9 |
2026-06-15 |
—
|
CVE-2026-54191
The Pods plugin for WordPress contains a security flaw affecting versions prior to 3.3.9, allowing malicious users to embed executable code into the site's content without needing authentication. This vulnerability arises from inadequate filtering of input data and subsequent display on web pages. As a result, users may inadvertently run injected scripts when visiting affected pages.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings